CVE-2018-20238
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.51% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-384
- Affected
- atlassian/crowd
- Source
- security@atlassian.com
References
- http://www.securityfocus.com/bid/107036Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/CWD-5361Vendor Advisory
- http://www.securityfocus.com/bid/107036Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/CWD-5361Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.